CVE-2025-4937: SourceCodester Apartment Visitor Management System profile.php sql injection
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4937?
CVE-2025-4937 has been declared as critical due to its potential for SQL injection exploitation.
How do I fix CVE-2025-4937?
To fix CVE-2025-4937, ensure proper input validation and sanitation on the 'mobilenumber' parameter in the /profile.php file.
Which software is affected by CVE-2025-4937?
CVE-2025-4937 affects the SourceCodester Apartment Visitor Management System version 1.0.
What type of vulnerability is CVE-2025-4937?
CVE-2025-4937 is classified as an SQL injection vulnerability.
What file is associated with CVE-2025-4937?
CVE-2025-4937 is associated with the /profile.php file in the affected software.